Zoek.exe v5.0.0.0 Updated 24-07-2014 Tool run by darline on za 26/07/2014 at 10:29:33,62. Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\darline\Desktop\zoek.exe [Scan all users] [Script inserted] [Checkboxes used] ==== System Restore Info ====================== 26/07/2014 10:32:41 Zoek.exe System Restore Point Created Succesfully. ==== Empty Folders Check ====================== C:\PROGRA~2\MSXML 4.0 deleted successfully C:\PROGRA~2\VideoLAN deleted successfully C:\PROGRA~2\COMMON~1\Symantec Shared deleted successfully C:\PROGRA~3\Oracle deleted successfully C:\Users\darline\AppData\Local\cache deleted successfully C:\Users\darline\AppData\Local\Sparta deleted successfully ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} deleted successfully HKEY_USERS\S-1-5-21-2390957687-3440449034-663207043-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} deleted successfully HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} deleted successfully HKEY_USERS\S-1-5-21-2390957687-3440449034-663207043-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} deleted successfully HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully HKEY_USERS\S-1-5-21-2390957687-3440449034-663207043-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully HKEY_USERS\S-1-5-21-2390957687-3440449034-663207043-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully HKEY_USERS\S-1-5-21-2390957687-3440449034-663207043-1001\Software\Microsoft\Internet Explorer\SearchScopes\{10EDB994-47F8-43F7-AE96-F2EA63E9F90F} deleted successfully HKEY_USERS\S-1-5-21-2390957687-3440449034-663207043-1001\Software\Microsoft\Internet Explorer\SearchScopes\{4453810D-E4C2-4850-89DD-183DBDCE012E} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} deleted successfully HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully ==== Deleting CLSID Registry Values ====================== HKEY_USERS\S-1-5-21-2390957687-3440449034-663207043-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{d2ce3e00-f94a-4740-988e-03dc2f38c34f} deleted successfully HKEY_USERS\S-1-5-21-2390957687-3440449034-663207043-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{e5c66dd8-308b-4a4f-af0a-3d04f25b5343} deleted successfully HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\URLSearchHooks\{4453810D-E4C2-4850-89DD-183DBDCE012E} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully ==== Running Processes ====================== C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\PskSvc.exe C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\TPSrvWow.exe C:\PROGRAM FILES (X86)\PANDA SECURITY\PANDA ANTIVIRUS PRO 2014\WebProxy.exe C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Windows\SysWOW64\svchost.exe C:\Windows\SysWOW64\svchost.exe c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe C:\Users\darline\AppData\Roaming\uTorrent\uTorrent.exe C:\Program Files (x86)\hp\Digital Imaging\bin\hpqtra08.exe C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe C:\Program Files (x86)\hp\HP Software Update\hpwuschd2.exe C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\ApVxdWin.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\PsCtrls.exe C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\PavFnSvr.exe C:\Program Files (x86)\Common Files\Panda Security\PavShld\pavprsrv.exe C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\pavsrvx86.exe C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\AVENGINE.EXE C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\PsImSvc.exe C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe C:\Program Files (x86)\hp\Digital Imaging\bin\hpqste08.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe C:\Users\darline\Desktop\zoek.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\SysWOW64\cmd.exe C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\psimreal.exe ==== Deleting Services ====================== HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\BBSvc deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BBSvc deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\BBSvc deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\BBSvc deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\SafeBoot\Network\BrowserProtect deleted successfully HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\Eventlog\Application\BrowserProtect deleted successfully ==== Registry Fix Code x64 ====================== Windows Registry Editor Version 5.00 [-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}] [HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run] ""=- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=- ==== Deleting Files \ Folders ====================== C:\Users\darline\AppData\Roaming\sparta111 deleted C:\Users\darline\.android deleted C:\Users\darline\AppData\Local\avgchrome deleted C:\Users\darline\Searches deleted C:\Windows\SysNative\config\systemprofile\Searches deleted C:\Users\darline\AppData\Roaming\Mozilla\Firefox\Profiles\a257194\searchplugins\bs-player-controlbar-customized-web-search.xml deleted C:\Users\darline\Inquisit_3040.exe deleted "C:\Windows\Installer\6e82bf.msi" deleted "C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE" deleted "C:\Program Files (x86)\Microsoft\BingBar" not deleted ==== System Specs ====================== Windows: Windows 7 Home Premium Edition (64-bit) Service Pack 1 (Build 7601) Memory (RAM): 4062 MB CPU Info: Pentium(R) Dual-Core CPU E5300 @ 2.60GHz CPU Speed: 2540,7 MHz Sound Card: Luidsprekers (Realtek High Defi | Display Adapters: Intel(R) G41 Express Chipset | Intel(R) G41 Express Chipset | RDPDD Chained DD | RDP Encoder Mirror Driver | RDP Reflector Display Driver Monitors: 1x; Compaq Q2159 Series Wide LCD Monitor | Screen Resolution: 1920 X 1080 - 32 bit Network: Network Present Network Adapters: D-Link AirPlus G DWL-G122 Wireless Adapter(rev.E) | Realtek PCIe FE Family Controller CD / DVD Drives: 1x (E: | ) E: hp CDDVDW TS-H653R Ports: COM Ports NOT Present. LPT Port NOT Present. Mouse: 3 Button Wheel Mouse Present Hard Disks: C: 452,6GB | D: 13,1GB Hard Disks - Free: C: 351,5GB | D: 2,3GB Manufacturer *: American Megatrends Inc. BIOS Info: AT/AT COMPATIBLE | 09/25/09 | HPQOEM - 20090925 Time Zone: Romance (standaardtijd) Motherboard *: FOXCONN ETON Country: Belgi‰ Language: NLB ==== System Specs (Software) ====================== Anti-Virus: Panda Antivirus Pro 2014 On-access scanning disabled (Outdated) Anti-Spyware: Panda Antivirus Pro 2014 disabled (Outdated) Anti-Spyware: Windows Defender disabled (Outdated) Default Browser: Google Chrome 36.0.1985.125 Internet Explorer Version: 11.0.9600.17207 Mozilla Firefox version: (3.6) Google Chrome version: 36.0.1985.125 Adobe Reader version: 11.0.07.79 Sun Java version: 1.7.0_65 (32-bit) Flash Player version: 14.0.0.145 Shockwave Player version: 11.5.6r606 ==== Files Recently Created / Modified ====================== ====== C:\Windows ==== ====== C:\Users\darline\AppData\Local\Temp ==== 2014-07-25 13:56:17 9C089EC3BA65B47823D43DCD447DC647 429128 ----a-w- C:\Users\darline\AppData\Local\Temp\BuenoSearchTB.exe 2014-07-25 08:13:54 A7ED81A0BB0F50C456CFD6048B9A5389 575544 ------w- C:\Users\darline\AppData\Local\Temp\is45637729\31452045_stp\AnyProtectScannerSetup.exe 2014-07-15 10:08:42 33803D27C576D76140CAB8BC98710395 586832 ------w- C:\Users\darline\AppData\Local\Temp\is45637729\31452360_stp\July15_www.sweet-page.com.exe 2014-07-12 13:27:49 0B813086A3400AAFA1639D08823FBD46 145928 ----a-w- C:\Users\darline\AppData\Local\Temp\utt6561.tmp.exe ====== Java Cache ===== 2014-07-17 08:22:51 527287EBEA8B0B11B6BF15ADDE57B928 21543 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\251ffa0b-32da1553 2014-07-17 08:22:51 20DEDB44C5891181E12B91DFC4A4046A 3719 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\60208350-5359d97f 2014-07-17 08:22:49 378DBF34C7C585237D6800B401F73972 1142 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17\1beead91-66c8b28d 2014-07-17 08:22:50 24B65BAFF42A5463CD20C8552C61C4BB 4252 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\40b55292-6f5ba50c 2014-07-17 08:22:50 11CD5CBA22EE2099129F07C83F14D12E 857 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21\1c005d55-782ed9b2 2014-07-17 08:22:50 C7595A34F83AA7C2E904F813B138437E 13717 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22\31489656-1dd24f54 2014-07-17 08:22:43 EB5E11FDD5A826E3081D3856A8AE12AF 550796 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23\68254157-1372ef14 2014-07-17 08:22:48 9B5E05C5BFDFAC47CD8662EBF672444F 5694 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24\26908598-30b322e9 2014-07-17 08:22:49 4811EADC97F83D17EA7B95FF4F224EA5 5088 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24\526b698-40f14d2d 2014-07-17 08:22:50 C4FCEA123FB7E46D47D00A95C476C5A5 4720 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27\7e3d80db-17ae1704 2014-07-17 08:22:53 9587AE807FD773861608B16F75606DAB 291 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\18d8bf5c-52d43de3 2014-07-17 08:22:49 69DA970DBC4A5CB99A72E038B1E054CC 142 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3\779d1cc3-34a3b298 2014-07-17 08:22:53 9566201EBD2648C45407D04F867844B8 4307 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\150b3020-2630b45f 2014-07-17 08:22:50 1BF1E4FBE023BF0477260F3FBF8A4211 14884 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32\6970d1e0-7a653d29 2014-07-17 08:22:53 0055834E92CFB8B2B1F1E1D2708811F3 2431 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\11b7a561-66943c6d 2014-07-17 08:22:50 D1016A06D98900D8A15EFA7511D516B8 927 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\3ca56b61-72b5a46b 2014-07-17 08:22:48 B30747862AEAC7E65DBF4FE3D84EB54C 1757 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38\39689e66-2d52c3fd 2014-07-17 08:22:53 4B11BAF0634D556327EFBA2D5DFA4B00 22392 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42\767d712a-1bbbdadf 2014-07-17 08:22:50 485F1EFCDD0997ABC8736119164A5E12 51276 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\714f9b2b-756f8623 2014-07-17 08:22:53 FC1E9CCFEA05623306EFCA6B86F6A921 2024 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45\625d5aad-496f2de6 2014-07-17 08:22:53 B4FE1B2F647E787F0EF3D7CD11F0341E 2209 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48\62f49330-58118501 2014-07-17 08:22:53 B7C15FF56F61F8D20FC3751C19200095 1058 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\46c4d0b1-18f2ac51 2014-07-17 08:22:50 C2462EDFC7219E2DFFA3AA5453A8646E 61138 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\5cef6372-465b2556 2014-07-17 08:22:53 04C27D58BA5B1EC9097F695A73C3175A 7868 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53\604b335-6ae2215e 2014-07-17 08:22:51 0F9DF91B2BE775C455D35E76EA445FD2 810 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53\be58c35-5df9528a 2014-07-17 08:22:53 BB1F1AC48AC87EF413FC7B58CC8BC406 468 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54\30eb02b6-5afbb118 2014-07-17 08:22:51 5FFA4EF27909D96DAF978BF7159CA391 4863 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55\735fe7f7-19d8a34a 2014-07-17 08:22:49 9235026D8D6A9BA03AD5652D2F8CE677 41273 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56\16a4c078-5a8a727c 2014-07-17 08:22:51 832B6E065FDF0FE600727E79DD177851 22065 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56\1e2271b8-5543457c 2014-07-17 08:22:51 3BB7C5A99575C23072FACDBB24A03A3C 394 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56\3045ca38-21330026 2014-07-17 08:22:51 A231BD19375F9D51CCB6B180B7D8D01D 3724 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56\4fe128b8-3ae37c77 2014-07-17 08:22:50 206A17008540D557AD6F271CC9F35059 13570 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56\652eef38-4f0be102 2014-07-17 08:22:51 4B787AA4AC7CC61E01EFF06C1FA6319E 4751 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56\8cfa738-3f1fb56e 2014-07-17 08:22:48 0A5A0F9DE00C8861999CAB0B69DC19BE 500 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\16612d79-197233d0 2014-07-17 08:22:49 0D93DFC7B0162B03D3AB10D9CE4DAFF8 10859 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\52fda3b9-314893fb 2014-07-17 08:22:50 F60D0C2A404DA4DE7B1FA858FF432FA4 4323 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62\70fddbe-56459826 2014-07-17 08:22:50 2FE75D74A75465A172AF24B60F5EF83C 1514 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62\7104edfe-147b9bf9 2014-07-17 08:22:51 9B00BC6E4C847228CA075D39B4CDA3BF 829 ----a-w- C:\Users\darline\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\734fb708-37152127 ====== C:\Windows\SysWOW64 ===== 2014-07-25 17:38:18 0DC5AF80D059DEC792B665ED598C6567 536576 ----a-w- C:\Windows\SysWOW64\sqlite3.dll 2014-07-21 10:52:08 86E39E9161C3D930D93822F1563C280D 1998168 ----a-w- C:\Windows\SysWOW64\D3DX9_43.dll 2014-07-17 08:12:18 7F26D694BC7E78958BE38D1D9AAFC2B9 272808 ----a-w- C:\Windows\SysWOW64\javaws.exe 2014-07-17 08:12:12 FFAECE8AEC1D9CCDCEC1C55C2CA450BA 175528 ----a-w- C:\Windows\SysWOW64\java.exe 2014-07-17 08:12:12 67BE34FBF29E783691C713517102E67E 175528 ----a-w- C:\Windows\SysWOW64\javaw.exe 2014-07-17 08:12:12 419094DF76A32252ECD70730382029ED 98216 ----a-w- C:\Windows\SysWOW64\WindowsAccessBridge-32.dll ====== C:\Windows\SysWOW64\drivers ===== ====== C:\Windows\Sysnative ===== 2014-07-21 10:52:08 7160FC226391C0B50C85571FA1A546E5 2401112 ----a-w- C:\Windows\Sysnative\D3DX9_43.dll ====== C:\Windows\Sysnative\drivers ===== 2014-07-15 07:13:07 D41D8CD98F00B204E9800998ECF8427E 0 ---ha-w- C:\Windows\Sysnative\drivers\Msft_User_WUDFUsbccidDriver_01_09_00.Wdf 2014-07-09 09:30:52 FA886682CFC5D36718D3E436AACF10B9 497152 ----a-w- C:\Windows\Sysnative\drivers\afd.sys ====== C:\Windows\Tasks ====== 2014-07-21 10:58:23 -------- d-----w- C:\Windows\Sysnative\Tasks\Sony Corporation ====== C:\Windows\Temp ====== ======= C:\Program Files ===== 2014-07-25 20:04:48 -------- d-----w- C:\Program Files\trend micro 2014-07-21 10:49:26 -------- d-----w- C:\Program Files\Common Files\Sony Shared ======= C:\PROGRA~2 ===== 2014-07-21 10:48:56 -------- d-----w- C:\PROGRA~2\COMMON~1\Sony Shared 2014-07-21 10:42:54 -------- d-----w- C:\PROGRA~2\Sony 2014-07-17 08:12:35 -------- d-----w- C:\PROGRA~2\COMMON~1\Java ======= C: ===== ====== C:\Users\darline\AppData\Roaming ====== 2014-07-21 10:47:22 -------- d-----w- C:\Users\darline\AppData\Roaming\Sony Corporation 2014-07-15 07:15:32 -------- d-----w- C:\Users\darline\AppData\Roaming\VASCO 2014-07-15 07:15:30 -------- d-----w- C:\Users\darline\AppData\Local\Package Cache ====== C:\Users\darline ====== 2014-07-25 19:53:04 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\darline\Desktop\RSITx64.exe 2014-07-25 19:51:34 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\darline\Downloads\RSITx64.exe 2014-07-21 10:46:42 -------- d-----w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PlayMemories Home 2014-07-21 10:44:02 -------- d-----w- C:\ProgramData\Sony Corporation ====== C: exe-files == 2014-07-25 20:04:49 9A2347903D6EDB84C10F288BC0578C1C 388608 ----a-w- C:\Program Files\trend micro\darline.exe 2014-07-25 19:53:04 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\darline\Desktop\RSITx64.exe 2014-07-25 19:52:23 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\darline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E53KK5US\RSITx64.exe 2014-07-25 19:51:34 8045ABB21A3BDD66A48E1ED5C0F0EF6A 1222144 ----a-w- C:\Users\darline\Downloads\RSITx64.exe 2014-07-25 17:35:34 B653DD91D5D6E519D3357A80A15A5DFB 1354223 ----a-w- C:\Users\darline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q0J5UZ7T\adwcleaner_3.216.exe 2014-07-25 16:00:04 58CFEB24D4AC902D42EB2D15E18C3110 728960 ----a-w- C:\Users\darline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q0J5UZ7T\SpyHunter-installer.exe 2014-07-25 14:19:34 CD2270D20EE61EE42F26874633F918D2 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-2390957687-3440449034-663207043-1001\$IGCM636.exe 2014-07-25 14:19:30 6C3D135A8FB8AA7732543DA1C4FF82DD 544 ----a-w- C:\$Recycle.Bin\S-1-5-21-2390957687-3440449034-663207043-1001\$IVXZHED.exe 2014-07-25 14:12:01 D3C54C3AEBFD9A42732EA6ADD3640B94 247202 ----a-w- C:\Users\darline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q0J5UZ7T\VuuPC_VO2_8907[1].exe 2014-07-25 14:10:30 AC4728B29314F7F2C1A42722587B76B0 16987136 ----a-w- C:\Users\darline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BMP11ZDX\AnyProtect[1].exe 2014-07-25 14:09:51 024AD16370A3B7956D484FC25D3B59C0 588719 ----a-w- C:\Users\darline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6L7IJMS1\Setup[1].exe 2014-07-25 13:56:17 F95CE3CD865D69BAB740DF595E927CC4 288344 ----a-w- C:\$Recycle.Bin\S-1-5-21-2390957687-3440449034-663207043-1001\$RVXZHED.exe 2014-07-25 13:56:17 DF463B4C69C1531D1DA7DA3E30E7F8B5 24677393 ----a-w- C:\$Recycle.Bin\S-1-5-21-2390957687-3440449034-663207043-1001\$RGCM636.exe 2014-07-25 13:56:17 9C089EC3BA65B47823D43DCD447DC647 429128 ----a-w- C:\Users\darline\AppData\Local\Temp\BuenoSearchTB.exe 2014-07-25 13:55:05 BDCA70DCC5B7368856AC6BC991203FCA 360296 ----a-w- C:\Users\darline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q0J5UZ7T\SoftonicDownloader_voor_vlc-media-player.exe 2014-07-25 08:13:54 A7ED81A0BB0F50C456CFD6048B9A5389 575544 ------w- C:\Users\darline\AppData\Local\Temp\is45637729\31452045_stp\AnyProtectScannerSetup.exe 2014-07-21 10:37:44 E849583E8308C8D37BD63DDD537A8203 2758680 ----a-w- C:\Users\darline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BMP11ZDX\PMHOME_3120DL.exe === C: other files == ==== Startup Registry Enabled ====================== [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun" [HKEY_USERS\S-1-5-21-2390957687-3440449034-663207043-1001\Software\Microsoft\Windows\CurrentVersion\Run] "Google Update"="C:\Users\darline\AppData\Local\Google\Update\GoogleUpdate.exe /c" "Facebook Update"="C:\Users\darline\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver" "swg"="C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" "uTorrent"="C:\Users\darline\AppData\Roaming\uTorrent\uTorrent.exe /MINIMIZED" [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce] "mctadmin"="C:\Windows\System32\mctadmin.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "hpsysdrv"="c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe" "HP Software Update"="c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe" "Easybits Recovery"="C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe" "UpdatePRCShortCut"="C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe C:\Program Files (x86)\Hewlett-Packard\Recovery UpdateWithCreateOnce Software\CyberLink\PowerRecover" "ArcSoft Connection Service"="C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" "hpqSRMon"="C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" "QuickTime Task"="C:\Program Files (x86)\QuickTime\QTTask.exe -atboottime" "APVXDWIN"="C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\APVXDWIN.EXE /s" "SCANINICIO"="C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\Inicio.exe" "Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" "PMBVolumeWatcher"="C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe" "HP Remote Solution"="%ProgramFiles%\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Google Update"="C:\Users\darline\AppData\Local\Google\Update\GoogleUpdate.exe /c" "Facebook Update"="C:\Users\darline\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver" "swg"="C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" "uTorrent"="C:\Users\darline\AppData\Roaming\uTorrent\uTorrent.exe /MINIMIZED" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=" " ==== Startup Registry Enabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="C:\Windows\system32\igfxtray.exe" "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" "Persistence"="C:\Windows\system32\igfxpers.exe" ==== Startup Registry Disabled x64 ====================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\HPADVISOR] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="HPADVISOR" "hkey"="HKCU" "command"="C:\\Program Files (x86)\\Hewlett-Packard\\HP Advisor\\HPAdvisor.exe view=DOCKVIEW" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NortonOnlineBackupReminder] "key"="SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="NortonOnlineBackupReminder" "hkey"="HKLM" "command"="\"C:\\Program Files (x86)\\Symantec\\Norton Online Backup\\Activation\\NobuActivation.exe\" UNATTENDED" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\swg] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="swg" "hkey"="HKCU" "command"="\"C:\\Program Files (x86)\\Google\\GoogleToolbarNotifier\\GoogleToolbarNotifier.exe\"" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder\C:^Users^darline^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Schermopname en Snel starten.lnk] "path"="C:\\Users\\darline\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\OneNote 2007 Schermopname en Snel starten.lnk" "backup"="C:\\Windows\\pss\\OneNote 2007 Schermopname en Snel starten.lnk.Startup" "backupExtension"=".Startup" "command"="C:\\PROGRA~2\\MICROS~2\\Office12\\ONENOTEM.EXE /tsr" "item"="OneNote 2007 Schermopname en Snel starten" ==== Startup Folders ====================== 2010-01-22 22:27:13 1241 ----a-w- C:\Users\darline\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.1 .lnk 2010-10-18 14:07:21 2105 ----a-w- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk ==== Task Scheduler Jobs ====================== C:\Windows\tasks\Adobe Flash Player Updater.job --a------ [Undetermined Task] C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2390957687-3440449034-663207043-1001Core.job --a------ C:\Users\darline\AppData\Local\Facebook\Update\FacebookUpdate.exe [11/07/2012 22:40] C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2390957687-3440449034-663207043-1001UA.job --a------ [Undetermined Task] C:\Windows\tasks\Google Software Updater.job --a------ C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [14/08/2012 15:21] C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ [Undetermined Task] C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ [Undetermined Task] C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2390957687-3440449034-663207043-1001Core.job --a------ C:\Users\darline\AppData\Local\Google\Update\GoogleUpdate.exe [12/12/2010 15:35] C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2390957687-3440449034-663207043-1001UA.job --a------ [Undetermined Task] ==== Other Scheduled Tasks ====================== "C:\Windows\SysNative\tasks\Adobe Flash Player Updater" [C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe] "C:\Windows\SysNative\tasks\CreateChoiceProcessTask" [C:\Windows\System32\browserchoice.exe] "C:\Windows\SysNative\tasks\FacebookUpdateTaskUserS-1-5-21-2390957687-3440449034-663207043-1001Core" [C:\Users\darline\AppData\Local\Facebook\Update\FacebookUpdate.exe] "C:\Windows\SysNative\tasks\FacebookUpdateTaskUserS-1-5-21-2390957687-3440449034-663207043-1001UA" [C:\Users\darline\AppData\Local\Facebook\Update\FacebookUpdate.exe] "C:\Windows\SysNative\tasks\Google Software Updater" [C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files (x86)\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskUserS-1-5-21-2390957687-3440449034-663207043-1001Core" [C:\Users\darline\AppData\Local\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\GoogleUpdateTaskUserS-1-5-21-2390957687-3440449034-663207043-1001UA" [C:\Users\darline\AppData\Local\Google\Update\GoogleUpdate.exe] "C:\Windows\SysNative\tasks\User_Feed_Synchronization-{A2ECB5F4-3EFB-4448-BEF3-A51E29EEEF7C}" [C:\Windows\system32\msfeedssync.exe] "C:\Windows\SysNative\tasks\Hewlett-Packard\HP Assistant\PC Health Analysis" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe] "C:\Windows\SysNative\tasks\Hewlett-Packard\HP Assistant\PC Tuneup" [C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe] "C:\Windows\SysNative\tasks\Sony Corporation\Sony Home Network Library\SOHLib SOHDms" [C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe] ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions] "smartwebprinting@hp.com"="C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3" [18/10/2010 16:09] [HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions] "smartwebprinting@hp.com"="C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3" [18/10/2010 16:09] ==== Firefox Extensions ====================== ProfilePath: C:\Users\darline\AppData\Roaming\Mozilla\Firefox\Profiles\a257194 - Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 - Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} AppDir: C:\Program Files (x86)\Mozilla Firefox - Default - %AppDir%\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} - Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} ==== Firefox Plugins ====================== Profilepath: C:\Users\darline\AppData\Roaming\Mozilla\Firefox\Profiles\a257194 E2CCA1B3BA59949AE16EC587E89A09BA - C:\Windows\SysWoW64\Adobe\Director\np32dsw.dll - Shockwave for Director / Shockwave for Director 4390CCD3790F8D9C427C0C29590C62D7 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll - Shockwave Flash D2B5242013356AF422A42B9FAA4056C2 - C:\Users\darline\AppData\Roaming\VASCO\VascoCardReaderPlugin\3.2.3.2\npVascoCardReaderPlugin.dll - VASCO Card Reader Plugin FB5621842FDABF9F8359775573498FBC - C:\Users\darline\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll - Google Update FF0D6F82A0EC13952E83B9439100E45D - C:\Users\darline\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll - Facebook Video Calling Plugin FD63DE29FE0A7E738BD81CA0EDDD8020 - C:\Users\darline\AppData\Roaming\VASCO\VascoCardReaderPlugin\3.2.3.2\npVascoCardReaderPlugin64.dll - VASCO Card Reader Plugin ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions lbgfiglojokgabdbhegbpjgojgppppgf - C:\Users\darline\AppData\Roaming\freegames4357\freegames4357.crx[] YouTube - darline\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Google Search - darline\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Google Wallet - darline\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda 20-20 3D Viewer for IKEA - darline\AppData\Local\Google\Chrome\User Data\Default\Extensions\nnbjlpbcjbhgeeloohnpbcfblhnkhffm Gmail - darline\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia DefaultTab - C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc ==== Chrome Fix ====================== C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="https://www.facebook.com/home.php?ref=home" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://www.google.com" "Search Page"="http://www.google.com" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://www.google.com" "Search Page"="http://www.google.com" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{4453810D-E4C2-4850-89DD-183DBDCE012E}" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{4453810D-E4C2-4850-89DD-183DBDCE012E}] not found New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="https://www.facebook.com/home.php?ref=home" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main] "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes] "DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}" ==== All HKCU SearchScopes ====================== HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes {012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}" {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR" {15954382-7C00-4FE7-A406-6F8B4FF4DF3F} Unknown Url="Not_Found" {763B4859-4C57-4B11-AFB4-A3949BAACCBF} Unknown Url="Not_Found" {8C291886-5073-486B-A772-289BD2C91E66} Unknown Url="Not_Found" {9E126360-D75D-4142-98AB-279939AC53E5} Netlog (NL) Url="http://nl.netlog.com/opensearch/view=search&q={searchTerms}" ==== Deleting CLSID Registry Keys ====================== HKEY_USERS\S-1-5-21-2390957687-3440449034-663207043-1001\Software\Microsoft\Internet Explorer\SearchScopes\{15954382-7C00-4FE7-A406-6F8B4FF4DF3F} deleted successfully HKEY_USERS\S-1-5-21-2390957687-3440449034-663207043-1001\Software\Microsoft\Internet Explorer\SearchScopes\{763B4859-4C57-4B11-AFB4-A3949BAACCBF} deleted successfully HKEY_USERS\S-1-5-21-2390957687-3440449034-663207043-1001\Software\Microsoft\Internet Explorer\SearchScopes\{8C291886-5073-486B-A772-289BD2C91E66} deleted successfully ==== Deleting CLSID Registry Values ====================== ==== Deleting Registry Keys ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\F60730A4A66673047777F5728467D401 deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\lbgfiglojokgabdbhegbpjgojgppppgf deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Google Updater deleted successfully HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4A03706F-666A-4037-7777-5F2748764D10} deleted successfully HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\F60730A4A66673047777F5728467D401 deleted successfully ==== HijackThis Entries ====================== F2 - REG:system.ini: UserInit=userinit.exe O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll O2 - BHO: Aanmeldhulp voor Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O4 - HKLM\..\Run: [hpsysdrv] c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe O4 - HKLM\..\Run: [HP Remote Solution] %ProgramFiles%\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe O4 - HKLM\..\Run: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe O4 - HKLM\..\Run: [UpdatePRCShortCut] "C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Recovery" UpdateWithCreateOnce "Software\CyberLink\PowerRecover" O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\APVXDWIN.EXE" /s O4 - HKLM\..\Run: [SCANINICIO] "C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\Inicio.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe O4 - HKCU\..\Run: [Google Update] "C:\Users\darline\AppData\Local\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [Facebook Update] "C:\Users\darline\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" O4 - HKCU\..\Run: [uTorrent] "C:\Users\darline\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE') O4 - Startup: OpenOffice.org 3.1 .lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\hp\Digital Imaging\bin\hpqtra08.exe O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Toon of verberg HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - http://cdn.scan.onecare.live.com/resource/download/scanner/en-us/wlscctrl2.cab O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab O16 - DPF: {95B5D20C-BD31-4489-8ABF-F8C8BE748463} (MSN Games – Hearts) - http://zone.msn.com/bingame/zpagames/zpa_hrtz.cab99160.cab O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} (MSN Games – Texas Holdem Poker) - http://zone.msn.com/bingame/zpagames/zpa_txhe.cab79352.cab O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) - http://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab102118.cab O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game.zylom.com/activex/zylomgamesplayer.cab O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-31-0.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O20 - AppInit_DLLs: O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe O23 - Service: Google Updateservice (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing) O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Panda Software Controller - Panda Security, S.L. - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\PsCtrls.exe O23 - Service: Panda Function Service (PAVFNSVR) - Unknown owner - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\PavFnSvr.exe O23 - Service: Panda Process Protection Service (PavPrSrv) - Unknown owner - C:\Program Files (x86)\Common Files\Panda Security\PavShld\pavprsrv.exe O23 - Service: Panda On-Access Anti-Malware Service (PAVSRV) - Panda Security, S.L. - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\pavsrvx86.exe O23 - Service: PMBDeviceInfoProvider - Sony Corporation - C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Panda IManager Service (PSIMSVC) - Panda Security S.L. - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\PsImSvc.exe O23 - Service: Panda PSK service (PskSvcRetail) - Panda Security, S.L. - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\PskSvc.exe O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: SeaPort - Unknown owner - C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (file missing) O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: Sony Digital Media Server (SOHDms) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe O23 - Service: Sony Device Searcher (SOHDs) - Sony Corporation - C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe O23 - Service: VAIO Entertainment Common Service (SpfService) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: Panda TPSrv (TPSrv) - Panda Security, S.L. - C:\Program Files (x86)\Panda Security\Panda Antivirus Pro 2014\TPSrvWow.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) ==== Empty IE Cache ====================== C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\darline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\darline\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully C:\Users\darline\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\darline\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully ==== Empty FireFox Cache ====================== C:\Users\darline\AppData\Local\Mozilla\Firefox\Profiles\a257194\Cache emptied successfully ==== Empty Chrome Cache ====================== C:\Users\darline\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== Flash Cache is not empty, a reboot is needed ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== C:\zoek_backup content ====================== ==== Empty Temp Folders ====================== C:\Users\darline\AppData\Local\Temp will be emptied at reboot C:\Users\Default\AppData\Local\Temp emptied successfully C:\Users\Default User\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully C:\Windows\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\Windows\Temp successfully emptied C:\Users\darline\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Program Files (x86)\Microsoft\BingBar" not found "C:\Users\darline\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\K8FM7PET\beeldbank.amsterdam.nl" not found "C:\Users\darline\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\K8FM7PET\boredonlinegames.com" not found "C:\Users\darline\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\K8FM7PET\cdn.ficgohub.com" not found "C:\Users\darline\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\K8FM7PET\g-ec2.images-amazon.com" not found "C:\Users\darline\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\K8FM7PET\koken.vtm.be" not found "C:\Users\darline\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\K8FM7PET\media.movieweb.com" not found "C:\Users\darline\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\K8FM7PET\nieuws.vtm.be" not found "C:\Users\darline\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\K8FM7PET\s1.adform.net" not found "C:\Users\darline\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\K8FM7PET\sadmin.brightcove.com" not found "C:\Users\darline\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\K8FM7PET\static.issuu.com" not found "C:\Users\darline\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\K8FM7PET\static.muzu.tv" not found "C:\Users\darline\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\K8FM7PET\tag.mediashakers.hiro.tv" not found "C:\Users\darline\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\K8FM7PET\toweltv.bbvms.com" not found "C:\Users\darline\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\K8FM7PET\v1nl.sftcdn.net" not found "C:\Users\darline\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\K8FM7PET\vitaya.be" not found "C:\Users\darline\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\K8FM7PET\vtm.be" not found "C:\Users\darline\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\K8FM7PET\www.bbc.co.uk" not found "C:\Users\darline\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\K8FM7PET\www.dieronderdak.be" not found "C:\Users\darline\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\K8FM7PET\www8.agame.com" not found ==== EOF on za 26/07/2014 at 11:04:31,91 ======================